Solved

Remote login failure

Posted on 2009-05-11
5
603 Views
Last Modified: 2012-05-06
Hi All,

I have recently enforced a new password policy in SBS 2003 requiring users to change their passwords.  This worked fine without a glitch at our local site, but we have some remote users connecting via VPN who are getting login failure alerts showing up on the server, presumably after just changing their passwords.

What is weird though is in the event ID logs it is showing a different name than our domain name next to the failed audit log.  Because they have strenuously assured me that they haven't changed the domain name and I can't verify it, I'm just wondering if it is at all possible that this could be anything other than an incorrect domain name entry? And if possible, why would it be displayed incorrectly in the audit logs?  

Logon Failure:
  Reason: Unknown user name or bad password
  User Name: bshort
  Domain: ASI-BRIAN
  Logon Type: 8
  Logon Process: Advapi
  Authentication Package: Negotiate
  Workstation Name: ASISERVER
  Caller User Name: NETWORK SERVICE
  Caller Domain: NT AUTHORITY
  Caller Logon ID: (0x0,0x3E4)
  Caller Process ID: 11172
  Transited Services: -
  Source Network Address: 217.165.94.157
  Source Port: 2350




0
Comment
Question by:Fritch84
  • 3
  • 2
5 Comments
 
LVL 4

Expert Comment

by:MattShadbolt
Comment Utility
can you ask the user to attempt to login DOMAINNAME\Username?
0
 
LVL 1

Author Comment

by:Fritch84
Comment Utility
Well they won't come on for another 6 hours or so (different time zones).  I'll definitely request that they try that.

Another weird thing is that I've been able to use their credentials to connect and it works fine for me.  I'm really hoping this is just a simple case of user error - their Internet was down at their site for some time (unrelated) so it's possible they tried to manipulate settings to try to connect.  

Does it make sense that there's something other than our real domain name listed in the event log next to the domain entry?
0
 
LVL 4

Expert Comment

by:MattShadbolt
Comment Utility
i totally agree Fritch. If the creds work on your machine than its more than likely user error.
0
 
LVL 1

Author Comment

by:Fritch84
Comment Utility
Thanks for the reassurance.  He sounded so adament that no other changes were made - but the incorrect logs and the fact it works for me completely contradicted him.  I was just wondering if this issue could occur from anything else that I enforced in the group policy.  I'll see how it goes this afternoon and let you know.  

0
 
LVL 1

Accepted Solution

by:
Fritch84 earned 0 total points
Comment Utility
The issue just miraculously disappeared...
0

Featured Post

Enabling OSINT in Activity Based Intelligence

Activity based intelligence (ABI) requires access to all available sources of data. Recorded Future allows analysts to observe structured data on the open, deep, and dark web.

Join & Write a Comment

A quick step-by-step overview of installing and configuring Carbonite Server Backup.
Let’s list some of the technologies that enable smooth teleworking. 
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

772 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

11 Experts available now in Live!

Get 1:1 Help Now